Study. uk . com
  1. Home
  2. All questions
  3. Question 43

CompTIA Security+ study material · question 43 of 611

A manager reports to the board that a vulnerability scan "proved the systems can be breached". Why is that claim unsupported?

  1. Scans cannot be run without rules of engagement
  2. A scan reports weaknesses; a penetration test attempts exploitation and demonstrates consequence
  3. Scan findings are always false positives until validated by the vendor
  4. Scans only run against internal systems
Show the answer

Answer: B. A scan reports weaknesses; a penetration test attempts exploitation and demonstrates consequence

Reporting a weakness is not the same as demonstrating it can be exploited to an outcome.

Source: NIST SP 800-115 (NIST) — SP 800-115 § 5 Target Vulnerability Validation Techniques

Challenge yourself on this topic → Study as cards